OVERVIEW CVE-2026-40885 is a credential disclosure vulnerability affecting goshs, a lightweight HTTP server written in Go, specifically versions 2.0.0-beta.4 through 2.0.0-beta.5. The flaw allows unauthenticated attackers to capture file-based access control list credentials by monitoring the server's public collaborator feed when global basic authentication is not enabled. SEVERITY The vulnerability has a moderate risk profile with a FAUCET Risk Score of 39.0/100 and an EPSS score of 0.000680. The attack requires network access to the collaborator websocket but no authentication, and exploitability is straightforward once credentials are captured. The impact is significant: attackers can read, upload, overwrite, and delete files within protected directories by replaying captured Authorization headers, potentially leading to data theft, integrity compromise, and service disruption. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and is marked as inactive on threat lists. However, the technical simplicity of the attack vector—passive monitoring of websocket traffic—may allow exploitation to occur undetected. The vulnerability was patched in version 2.0.0-beta.6, and users should upgrade immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta4:*:*:*:go:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:goshs:goshs:2.0.0:beta5:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.